note 61430 deleted from ref.mail by didou

From: Date: Sun, 23 Apr 2006 22:46:07 +0000
Subject: note 61430 deleted from ref.mail by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-109222@lists.php.net to get a copy of this message
Note Submitter: chris AT NOSPAM NIXLABS <<DOT>> COM ---- If you would also like to completely blacklist a person trying to perform injection, here is a useful method which exploits the inheritance behavior of .htaccess. The htaccess file should contain nothing else. This is useful on hosted sites, where you cannot alter firewall rules on the fly. function DenyIP($ip) { $htaccess = "/path/to/some/.htaccess" /* Make sure we have write access to the files */ if (is_writable($htaccess)) { /* Read in current deny list */ $cur_lst = trim(file_get_contents(HTACCESS)); /* Appending to the list */ if (!empty($cur_lst)) { $arr = explode("\n",$cur_lst); foreach ($arr as $str) trim($str); $arr[count($arr) - 1] = "deny from " . $ip; } else { /* Blank htaccesss case */ $arr = Array(); $arr[] = "order allow,deny"; $arr[] = "deny from " . $ip; } /* Our implicit allow all */ $arr[] = "allow from all"; $new_lst = implode("\n",$arr); $hand = fopen($htaccess,"wb"); if (!$hand) return; fwrite($hand, $new_lst); fclose($hand); } }

« previous php.notes (#109222) next »